Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=blog.brasilhosp.com.br
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: blog.brasilhosp.com.br
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 20 Dec 2014 10:05:20 GMT
Location: http://webinhost.com.br/blog
Server: Apache
Vary: Accept-Encoding
Content-Length: 236
Content-Type: text/html; charset=iso-8859-1
...236 bytes of data.
GET / HTTP/1.1
Host: blog.brasilhosp.com.br
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 20 Dec 2014 10:05:20 GMT
Location: http://webinhost.com.br/blog
Server: Apache
Vary: Accept-Encoding
Content-Length: 236
Content-Type: text/html; charset=iso-8859-1
...236 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: blog.brasilhosp.com.br
Referer: http://www.google.com/search?q=blog.brasilhosp.com.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: blog.brasilhosp.com.br
Referer: http://www.google.com/search?q=blog.brasilhosp.com.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://blog.brasilhosp.com.br/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 20 Dec 2014 10:05:20 GMT Location: http://webinhost.com.br/blog Server: Apache Vary: Accept-Encoding Content-Length: 236 Content-Type: text/html; charset=iso-8859-1 | clean |
http://webinhost.com.br/blog | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=3600 Connection: close Date: Sat, 20 Dec 2014 10:05:21 GMT Location: http://webinhost.com.br/blog/ Server: Apache Vary: Accept-Encoding Content-Length: 237 Content-Type: text/html; charset=iso-8859-1 Expires: Sat, 20 Dec 2014 11:05:21 GMT | clean |
http://webinhost.com.br/blog/ | 200 OK Content-Length: 152848 Content-Type: text/html | clean |
http://webinhost.com.br/blog/wp-content/cache/minify/000000/XYxLDsIwEEMvFM20ULHgMmgSjUJCfmRSVDg9JbAJG8vPtjyhqVlEh2xu6AUbac1VTX_xi9ODq_DFUghcn-raWpEzInnawOZsA1NxAibHnmFwWtDf132MM5xg-QFEl8CL2k_FVFdat9_u4yKntcs80GGg40DLGw.js | 200 OK Content-Length: 165109 Content-Type: application/x-javascript | clean |
https://webinhost.com.br/js/menu/menu5.js | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=0 Connection: close Date: Sat, 20 Dec 2014 10:05:27 GMT Location: http://www.webinhost.com.br/js/menu/menu5.js Server: Apache Vary: Accept-Encoding Content-Length: 252 Content-Type: text/html; charset=iso-8859-1 Expires: Sat, 20 Dec 2014 10:05:27 GMT | clean |
http://www.webinhost.com.br/js/menu/menu5.js | 200 OK Content-Length: 3161 Content-Type: application/javascript | clean |
http://webinhost.com.br/blog/wp-content/cache/minify/000000/S8rJT9cvL9DNzEvOKU1JLdbPAqLC0tSiSiilk0RIhW5uZnpRYkmqXm5mHgA.js | 200 OK Content-Length: 103002 Content-Type: application/x-javascript | clean |
http://webinhost.com.br/blog/wp-content/plugins/upprev-nytimes-style-next-post-jquery-animated-fly-in-button/upprev_js.php?ver=4.1 | 200 OK Content-Length: 1501 Content-Type: text/javascript | clean |
http://twitter.com/javascripts/blogger.js | HTTP/1.1 301 Moved Permanently Date: Sat, 20 Dec 2014 10:05:31 UTC Location: https://twitter.com/javascripts/blogger.js Server: tsa_b Content-Length: 0 Set-Cookie: guest_id=v1%3A141906993190929287; Domain=.twitter.com; Path=/; Expires=Mon, 19-Dec-2016 10:05:31 UTC X-Connection-Hash: 8570157ebe1dc256462787807c15727d X-Response-Time: 2 | clean |
https://twitter.com/javascripts/blogger.js | 404 Not Found Content-Length: 4311 Content-Type: text/html | clean |
https://abs.twimg.com/errors/404-4f54405af9c0bcdecbe656ca8893f7a9.js | 200 OK Content-Length: 10803 Content-Type: application/javascript | clean |
https://twitter.com/ | 200 OK Content-Length: 57982 Content-Type: text/html | clean |
https://abs.twimg.com/c/swift/en/init.7fcc8b6af2c42d952bd862db8b538d9a961e7340.js | 200 OK Content-Length: 300096 Content-Type: application/javascript | clean |
https://twitter.com/?lang=id | 200 OK Content-Length: 58476 Content-Type: text/html | clean |
https://abs.twimg.com/c/swift/id/init.7b4bdba79ace76ac0046365f4317e867b586fb80.js | 200 OK Content-Length: 300605 Content-Type: application/javascript | clean |
https://twitter.com/?lang=msa | 200 OK Content-Length: 59534 Content-Type: text/html | clean |
https://abs.twimg.com/c/swift/msa/init.9f4318ec495d8703a17c2991a4861ab4eed2e0bf.js | 200 OK Content-Length: 303104 Content-Type: application/javascript | clean |
https://twitter.com/?lang=cs | 200 OK Content-Length: 58889 Content-Type: text/html | clean |
https://abs.twimg.com/c/swift/cs/init.427d4641f778c30beacd5431348ff6e204033799.js | 200 OK Content-Length: 303104 Content-Type: application/javascript | clean |